1. About this Policy
This Privacy Policy ("Policy") applies to all personal information collected, used, disclosed and otherwise handled by ECHO Projects in connection with the Grant Scan web application, Tender Scan module, associated mobile experiences, customer support interactions, payment processing, email communications, and any related services (collectively, the "Services").
By creating an account, using the Services, submitting personal information through any form or feature, or continuing to use the Services after any update to this Policy, you acknowledge that you have read and understood it. If you do not agree with any part of this Policy, you should not use the Services or provide personal information to us.
If you use the Services on behalf of an organisation, you represent and warrant that you are authorised to provide personal information about that organisation and its representatives, that doing so does not breach any obligation of confidentiality or privacy, and that you have made those individuals aware of relevant information about how their data will be handled.
This Policy supplements but does not replace our Terms of Service. In the event of any conflict between this Policy and our Terms of Service on a privacy matter, this Policy prevails to the extent of the inconsistency on that privacy matter.
2. Who we are
The data controller responsible for personal information collected through the Services is ECHO Projects, an Australian social enterprise that operates Grant Scan and Tender Scan.
ECHO Projects — Privacy Contact
Email: Admin@ECHOProjects.org
Phone: 0493 051 823
Website: grantscan.echoprojects.org
Parent organisation: www.echoprojects.org
Grant Scan is a software product developed and operated by ECHO Projects to help Australian nonprofits, charities, community organisations, social enterprises, and businesses identify and track grant and government procurement (tender) opportunities. Tender Scan is a module within the same platform focusing on Australian government procurement via AusTender and related sources.
3. Legal framework and privacy commitments
We aim to manage personal information in accordance with the Australian Privacy Principles (APPs) contained in Schedule 1 of the Privacy Act 1988 (Cth). The APPs regulate transparency, anonymity and pseudonymity, collection, use and disclosure, direct marketing, cross-border disclosure, the adoption of government identifiers, data quality, data security, access, and correction.
We also take into account the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act, which requires us to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when there is reasonable grounds to believe an eligible data breach has occurred that is likely to result in serious harm.
We take into account the Privacy and Other Legislation Amendment Act 2024 (Cth), including upcoming transparency requirements for automated decision-making commencing in December 2026, and we have drafted this Policy to be consistent with those anticipated requirements. We take into account the Spam Act 2003 (Cth) for all electronic marketing and commercial communications.
Where applicable, we also consider NSW privacy guidance, including the Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act) and Health Records and Information Privacy Act 2002 (NSW) (HRIP Act) as good-practice benchmarks, even though Grant Scan is not a NSW public sector agency and those Acts primarily regulate the NSW public sector.
Core privacy commitments
- We collect personal information only where reasonably necessary for the Services, our legitimate business operations, legal compliance, or with your consent.
- We are transparent about what we collect, why, who we share it with, and how you can access, correct or complain about our handling of your information.
- We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure.
- We do not sell personal information to third parties under any circumstances.
- We do not use personal information for targeted advertising purposes, nor do we share personal information with advertising networks or data brokers.
- We do not intentionally collect sensitive information (including health information, racial or ethnic origin, religious beliefs, criminal records, or biometric data) unless it is provided by you voluntarily, is necessary for a lawful purpose you have initiated, or is required or authorised by law.
- We maintain documented processes for privacy enquiries, access requests, correction requests, complaints, and data breach assessment and notification.
- We comply with data minimisation principles — we only collect what is genuinely needed and seek to delete or de-identify information when it is no longer required.
4. What personal information we collect
The specific personal information we collect depends on how you use the Services. Under the Privacy Act, "personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
| Information type | Examples and details |
|---|---|
| Identity and contact | Full name, email address, phone number (if provided voluntarily), account login identifiers, IP address, and any identifiers provided during account registration or correspondence. |
| Organisation and eligibility | Organisation name, type (e.g. nonprofit, charity, social enterprise, SME), ABN or ACN (if provided), DGR status, state or region, geographic delivery area, website URL, sector, organisational stage, funding range, certifications, and other information relevant to grant or tender eligibility. |
| Project and scan content | Project names, project descriptions, capabilities descriptions, industry sector tags, grant searches, tender searches, saved grants, saved tenders, saved searches, watchlists, checklist notes, scan results, AI-generated match scores, eligibility summaries, match reasons, AI recommendations, and related application planning materials. |
| Subscription, billing and access | Subscription plan, tier, billing cycle, payment status, invoices, Stripe customer ID, Stripe session ID, access code redemption records (code value, redemption timestamp, tier granted, expiry), renewal dates, and billing metadata. We do not store full payment card numbers or CVV data — these are handled exclusively by Stripe. |
| Uploaded documents | Grant guidelines, application drafts, organisational documents, project documents, financial documents, and any other files uploaded by you for use with the platform features. You are responsible for ensuring these files do not contain unnecessary sensitive information about third parties. |
| Support and communications | Support messages, emails, feedback submissions, complaint records, chat logs, enquiry forms, and related correspondence. |
| Usage, device and log data | IP address, approximate geolocation (city/region level), browser type and version, operating system, device type, screen size, session timestamps, pages viewed, features used, referring URLs, click events, scan trigger events, error logs, and feature interaction data. |
| Derived and generated data | AI-generated grant or tender match scores, eligibility notes, summaries, saved search outputs, scan run identifiers, diagnostic records, embedding vectors generated from your project or organisation descriptions, and system-generated recommendations. |
Sensitive information
Sensitive information is a subset of personal information that attracts a higher level of protection under the APPs. It includes health information, racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, and biometric information or templates.
We do not request sensitive information for ordinary use of Grant Scan or Tender Scan. However, if you voluntarily include sensitive information in your project descriptions, organisation descriptions, uploaded documents or other free-text fields — for example, mentioning that your organisation supports a particular health community or ethnic group — you consent to us handling that information for the purpose of delivering the Services, consistent with this Policy and applicable law. We will not use such information for any secondary purpose without your consent.
We ask you not to upload medical records, health information about identifiable individuals, criminal record information about identifiable individuals, or biometric data. If you inadvertently do so, please contact us immediately so we can assess and delete the information.
Government identifiers
We may collect an ABN, ACN or similar organisation identifier where relevant to grant or tender eligibility assessments. We do not use Australian government identifiers (such as a Tax File Number or Medicare number) as our own identifier for individuals. We do not collect Tax File Numbers under any circumstances. We may collect ABNs solely as an organisational identifier relevant to eligibility, not as an individual identifier.
Health information
We do not request or require health information as part of our Services. If health information is incidentally included in a project description, document, or communication, it will be handled consistently with this Policy and, to the extent it constitutes health information within the meaning of the HRIP Act (NSW) or relevant federal law, we will take appropriate care. Users should avoid including individually identifiable health information unless it is strictly necessary for the grant or tender application they are preparing.
5. How we collect personal information
We collect personal information through the following means:
Directly from you
- When you create an account, log in, or manage your profile.
- When you run a grant scan or tender scan by entering project or organisation information.
- When you save a grant, save a tender, save a search, or build a watchlist.
- When you upload documents, such as grant guidelines, project plans, or organisational materials.
- When you subscribe to a plan, redeem an access code, or manage your billing.
- When you contact our support team via email, phone, form, or any other channel.
- When you provide feedback, complete a survey, or correspond with us.
Automatically through your use of the Services
- Log data collected by our hosting and infrastructure provider (Base44), including your IP address, browser, device, operating system, pages visited, session timestamps, and referral URLs.
- Analytics events we instrument to understand how features are used, which pages are visited, and where errors occur.
- Cookies and similar local storage technologies (described in detail in Section 12).
- Stripe may collect payment-related data and device fingerprinting data as part of checkout and fraud prevention.
From third parties and public sources
- From our infrastructure and authentication provider (Base44) in connection with account management and session handling.
- From Stripe in connection with payment status, subscription status, and billing events.
- From publicly available government sources, such as AusTender (business.gov.au/grants) and philanthropic funding databases, to populate our grant and tender database. This may include publicly listed organisation names in connection with procurement outcomes.
- From administrators or team members who manage records or users on your behalf.
Anonymity and pseudonymity
Where lawful and practicable, you may interact with parts of the Services anonymously or using a pseudonym — for example, browsing publicly visible pages. However, account creation, running a scan, saving results, redeeming an access code, managing a subscription, and accessing customer support all require accurate identifying information. Providing false identity information may breach our Terms of Service.
6. Why we use personal information
We use personal information only for the primary purpose for which it was collected, for related secondary purposes that you would reasonably expect in the context, or where otherwise permitted or required by law.
Service delivery
- Creating, authenticating, and managing user accounts, team access, and administrative permissions.
- Processing grant and tender scans — including transmitting project or organisation descriptions to AI services for matching, scoring, and summarisation.
- Displaying, saving, and managing grant results, tender results, saved searches, watchlists, project profiles, checklists, and uploaded documents.
- Verifying access code redemptions and managing subscription entitlements, tiers, and expiry.
- Processing payments, subscriptions, plan changes, cancellations, refunds, and billing portal access through Stripe.
- Sending transactional and service communications, including subscription confirmation, payment receipts, grant alerts, account notices, and security alerts.
- Providing customer support, troubleshooting, and responding to enquiries and complaints.
Improvement, security, and compliance
- Monitoring, testing, maintaining, debugging, and improving the Services.
- Detecting and preventing misuse, fraud, unauthorised access, security incidents, and abuse of the platform.
- Maintaining business records and meeting legal, tax (including ATO obligations), accounting, audit, and regulatory requirements.
- Responding to lawful requests from courts, regulators, law enforcement, and government agencies.
- Enforcing our Terms of Service, protecting our legal rights and interests, and resolving disputes.
- Producing aggregate or de-identified analytics and product usage reports that do not reasonably identify individuals.
Purposes we do not use your information for
- We do not sell personal information to any third party.
- We do not share personal information with advertisers, advertising networks, or data brokers.
- We do not use personal information for political profiling, insurance profiling, or credit assessment.
- We do not use your project descriptions or grant content to train our own AI models or to train any third-party models under our current service agreements.
7. AI, automated processing and grant/tender recommendations
Grant Scan and Tender Scan use automated processing, semantic embedding technology, and large language model (LLM) AI services to analyse user-provided project or organisation information, compare it against a database of grant and tender opportunities, and produce ranked recommendations, eligibility summaries, match scores, and related outputs.
What data is transmitted to AI providers
When you run a grant scan or tender scan, information you have provided — including project descriptions, organisation descriptions, sector tags, state/location, organisation type, funding range, and related parameters — may be transmitted to our AI processing provider, currently OpenAI, L.L.C. (United States), via its API. We take reasonable steps to minimise the transmission of directly identifying personal information (such as names or contact details) for AI processing purposes. Where possible, we transmit functional content rather than personal identifiers.
Under our current API agreement with OpenAI, data submitted via the API is not used by OpenAI to train or improve their AI models. We recommend you review OpenAI's privacy policy and API data usage policy at openai.com/privacy for current terms.
What you should not include in free-text fields
- Full names, contact details, or sensitive information about identifiable third parties.
- Health, medical, or clinical information about identifiable individuals.
- Information about children under 16.
- Confidential commercial information subject to non-disclosure agreements.
- Financial account numbers, tax file numbers, passwords, or authentication credentials.
Accuracy and limitations of AI outputs
AI-generated outputs may be incomplete, outdated, inaccurate, or based on grant or tender information that has changed since our database was last updated. Grant and tender databases are updated periodically but may not reflect the most current opportunity listings, eligibility rule changes, or deadline changes. You must independently verify all information before acting on it.
Automated decision-making
We do not make decisions with legal or similarly significant effect about individuals solely by automated means without human involvement. Scan results are recommendations for your review — no automated system makes a decision that determines your eligibility, your right to apply, or your entitlement to any grant or contract. In keeping with the Privacy and Other Legislation Amendment Act 2024 (Cth) transparency requirements commencing December 2026, we commit to maintaining clear disclosure about how automated processing contributes to the outputs you receive.
Embedding vectors
We generate numerical embedding vectors from your project or organisation descriptions using AI models. These vectors are stored in our database to power similarity matching. They are derived representations of your content and are not intelligible as plain text. They are used solely for matching purposes within the Services and are deleted or de-identified when your associated records are removed.
8. Disclosure of personal information and service providers
We do not sell personal information. We may disclose personal information to third parties where:
- It is reasonably necessary to provide or support the Services.
- You have consented, or the disclosure is for a purpose you would reasonably expect.
- It is required or authorised by Australian law, including a court order, subpoena, statutory notice, or regulatory request.
- We believe in good faith that disclosure is necessary to prevent a serious and imminent threat to the life, health, or safety of an individual or the public.
- We are involved in a corporate transaction such as a merger, acquisition, restructure, or asset sale, in which case personal information may be disclosed to the relevant counterparty subject to equivalent confidentiality obligations.
Current service providers (subprocessors)
| Provider | Location | Purpose |
|---|---|---|
| Base44 | United States | Application hosting, database, authentication, file storage, backend infrastructure, serverless functions, API gateway, and platform services. All primary application data is stored in Base44 infrastructure. |
| Stripe Inc. | United States | Payment processing, subscription management, checkout sessions, invoices, billing portals, fraud prevention, and payment authentication. Stripe has its own privacy policy at stripe.com/au/privacy. |
| OpenAI, L.L.C. | United States | AI language model processing for grant and tender matching, eligibility scoring, summarisation, recommendation generation, and embedding vector creation. Project descriptions and related content may be transmitted to OpenAI. OpenAI API data is subject to their data processing addendum. Transmitted data is not used to train OpenAI models under our API agreement. |
| Email and notification providers | May vary | Transactional emails, grant alert notifications, subscription confirmation, account notices, password resets, and service communications. Providers are selected on the basis of data security and reliability. |
| Analytics and monitoring providers | May vary | Aggregate usage analytics, performance monitoring, error tracking, uptime monitoring, audit logs, abuse prevention, and security incident detection. Analytics data is primarily aggregate and de-identified where practicable. |
| Professional advisers | Australia | Legal counsel, accountants, tax advisers, insurers, auditors, and dispute resolution professionals as required from time to time. |
| Regulators, courts and government | Australia and may vary | Where required or authorised by law, including response to subpoenas, statutory notices, court orders, regulatory investigations, or mandatory reporting obligations. |
We take reasonable steps to ensure that our service providers handle personal information consistently with confidentiality, security, and privacy obligations appropriate to their role and the sensitivity of the information. Where appropriate, we rely on contractual data processing terms, security commitments, and published policies.
9. Overseas disclosure and cross-border data flows
The Services are hosted and processed using infrastructure that may store or process data outside Australia. Key international data flows include:
- Base44 (application infrastructure and database) — servers may be located in the United States or other jurisdictions where cloud infrastructure is operated.
- Stripe (payment processing) — Stripe operates globally with infrastructure in the United States and EU. Stripe is certified under various international data protection frameworks.
- OpenAI (AI processing) — OpenAI operates in the United States. Data submitted via the API is subject to OpenAI's API data usage policy and data processing addendum.
- Email and notification providers — may operate in Australia, the United States, or EU.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information (APP 8.1), including by relying on contractual data processing terms, security certifications, and provider compliance frameworks. We note that overseas privacy laws and protections may differ from Australian law, and once data is disclosed overseas, the Privacy Act may not apply to how the overseas entity handles it.
By using the Services, you acknowledge that your personal information may be transferred to, stored, and processed in countries outside Australia, including the United States, and you consent to such transfer where it is necessary for the delivery of the Services.
10. Security of personal information
We take reasonable steps to protect personal information we hold from misuse, interference, loss, unauthorised access, modification, and disclosure (APP 11.1). Our security measures include:
- HTTPS/TLS encryption for all data transmitted between your device and our Services.
- Provider-managed encryption at rest for data stored in our infrastructure.
- Role-based access controls restricting access to personal information to personnel and service providers with a genuine operational need.
- Payment processing via Stripe — we do not store, transmit, or process raw payment card numbers or CVV data ourselves; all payment information is handled exclusively by Stripe's PCI-DSS compliant systems.
- System logging, monitoring, alerting, and backup controls operated through our infrastructure provider.
- Reasonable vendor due diligence, password policy controls, and account protection practices.
- Prompt deletion, de-identification, or access restriction when information is no longer required, subject to lawful retention obligations.
No internet or cloud-based service can guarantee absolute security. You are responsible for maintaining the security of your login credentials, using a strong password, protecting access to your email account, logging out of shared devices, and notifying us immediately if you suspect your account has been compromised or subject to unauthorised access.
Notifiable data breaches
If we identify or suspect a data breach, we will promptly assess whether it constitutes an "eligible data breach" under Part IIIC of the Privacy Act — that is, whether there has been unauthorised access to or disclosure of personal information (or loss of personal information in circumstances where unauthorised access or disclosure is likely), and whether this is likely to result in serious harm to one or more affected individuals.
If we determine that an eligible data breach has occurred, we will, as soon as practicable:
- Notify the Office of the Australian Information Commissioner (OAIC) using the required form.
- Notify affected individuals whose personal information was involved, including a description of the breach and recommendations about steps they should take in response.
- Take all reasonable steps to contain, remediate, and prevent recurrence of the breach.
We maintain an internal data breach response plan and will conduct a root cause analysis following any confirmed breach. You can report a suspected data breach or security vulnerability to Admin@ECHOProjects.org.
11. Data retention, deletion and de-identification
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, for related business operations, for dispute resolution, for security and integrity purposes, or as required or authorised by Australian law — including the Income Tax Assessment Act 1997 (Cth) and relevant accounting and audit standards.
| Record type | Indicative retention approach |
|---|---|
| Account and identity records | While your account is active, plus a reasonable post-closure period for residual resolution, generally up to 12 months. We may de-identify rather than delete where permitted. |
| Billing, invoices and transaction records | Generally 7 years from the date of transaction to meet Australian tax law (ITAA 1997), accounting standards, ATO record-keeping rules, and audit obligations. |
| Access code redemption records | Generally 7 years from redemption to support subscription verification, dispute resolution, and regulatory compliance. |
| Grant and tender searches, saved results, project records | While needed to provide the Services, or until you delete them, close your account, or request deletion — subject to lawful retention obligations. |
| Uploaded documents | Until deleted by you, replaced, or account closure, subject to backup overwrite cycles and lawful retention. |
| Support and complaint records | Generally up to 3 years after final resolution, or longer if required for ongoing legal, regulatory or dispute purposes. |
| Security, audit and access logs | Generally up to 24 months, unless retained for security investigation, fraud prevention, incident response, or legal compliance. |
| AI-generated outputs and embeddings | Retained while the associated user account and project/submission records are active, then deleted or de-identified on account closure subject to residual backup cycles. |
| De-identified analytics | May be retained indefinitely where information can no longer reasonably identify an individual. |
When personal information is no longer required, we take reasonable steps to destroy or de-identify it. "De-identification" means removing or altering information so that it can no longer reasonably identify an individual. Deletion from active production systems may not immediately remove information from encrypted backups, archived logs, or disaster recovery snapshots. Backup copies are overwritten or destroyed through standard backup rotation cycles unless restoration is required for security, operational continuity, or legal reasons.
You may request deletion of your account and personal data at any time by contacting us (see Section 18). We will process your request within a reasonable time, subject to our legal obligations to retain certain records (particularly billing and transaction records for 7 years under Australian tax law).
12. Cookies, tracking technologies and analytics
We use cookies, local storage, session storage, and similar technologies to operate the Services, maintain login sessions, remember preferences, support payment processing, maintain security, understand product usage, and improve performance.
Types of cookies and tracking we use
- Essential / functional cookies: Required for authentication, login session management, security controls, and core platform functionality. These cannot be disabled without breaking the Services.
- Preference cookies: Store settings and user interface preferences to improve your experience across sessions.
- Analytics and event tracking: We may collect aggregate, de-identified data about feature usage, page visits, scan activity, performance, and errors to improve the Services. We aim to minimise personally identifying data in analytics.
- Payment / fraud prevention cookies: Stripe uses cookies and similar technologies as part of its payment, checkout, and fraud detection processes. These are governed by Stripe's own cookie and privacy policies.
You can manage or disable cookies through your browser settings. Blocking essential cookies will likely prevent login, checkout, subscription management, and other core platform features from functioning properly. We do not currently respond to browser "Do Not Track" (DNT) signals, as there is no consistent or legally required industry standard for interpreting those signals in Australia.
13. Direct marketing and commercial electronic messages
We may send you commercial electronic messages (as defined in the Spam Act 2003 (Cth)) where we have your express or inferred consent and the message complies with the requirements of that Act — including clear sender identification, a functional unsubscribe mechanism, and a genuine physical or electronic address.
Transactional communications (not marketing)
The following are transactional or service communications that are not subject to marketing opt-out, as they are necessary for the operation of your account or the Services:
- Account creation, email verification, and password reset messages.
- Subscription confirmation, renewal reminders, plan change confirmations, and payment receipts.
- Grant and tender alert notifications you have specifically configured and requested within the Services.
- Security alerts, suspected unauthorised access notifications, and critical service notices.
- Privacy breach notifications required under the NDB scheme.
- Support responses to enquiries you have initiated.
- Policy update notifications for material changes.
Opting out of marketing
You may opt out of non-essential marketing or promotional communications at any time by using the unsubscribe link included in any such message, or by contacting us at Admin@ECHOProjects.org. We will process opt-out requests promptly, and in any event within 5 business days as required by the Spam Act. Opting out of marketing will not affect the receipt of transactional or service communications described above.
14. Access codes, subscriptions and billing data
To use the core scan features of Grant Scan, users must redeem a valid access code or hold an active subscription. Access codes are issued by ECHO Projects and grant tiered access for defined periods.
Access code data
- When you redeem an access code, we record the code value, the date and time of redemption, the user account that redeemed it, the tier granted (e.g. Pro or Premium or Trailblazer), and the resulting access expiry date.
- Access code records are retained for generally 7 years for dispute resolution, fraud prevention, and audit purposes.
- Access codes are single-use or multi-use as configured. Attempting to share, resell, or misuse access codes may constitute a breach of our Terms of Service.
Subscription and billing data
- Subscription management, payment processing, and billing are handled by Stripe. We do not store your payment card number, CVV, or bank account details.
- We store Stripe customer identifiers, subscription plan identifiers, billing cycle information, and payment status flags in our database to manage your account entitlements.
- Billing and transaction records are retained for generally 7 years to comply with Australian tax and accounting obligations.
- You can access your billing history, update payment methods, and manage your subscription through the Stripe billing portal accessible via your Account settings.
15. Uploaded documents and user-generated content
Grant Scan allows you to upload files (such as grant guidelines, project plans, and organisational documents) for use within the platform features, including the Guidelines Scanner and Document Vault.
- Uploaded documents are stored on our infrastructure provider (Base44) and are accessible only to your user account and administrators.
- Documents may be processed by AI services (OpenAI) where you use features that analyse their content, such as the Guidelines Scanner.
- You are responsible for ensuring that any documents you upload do not contain the personal information of third parties unless you have authority to share that information and doing so is consistent with applicable privacy law.
- You should not upload documents containing sensitive information about identifiable individuals (including health records, financial records, or criminal history) unless it is strictly necessary and you have the appropriate authority and consents.
- Uploaded documents are retained until you delete them, your account is closed, or we determine they are no longer required, subject to backup cycles and lawful retention obligations.
- Upon account closure or a deletion request, we will take reasonable steps to delete your uploaded documents from active systems within a reasonable time, subject to backup overwrite cycles.
16. Third-party links and external services
The Services may contain links to external websites, government portals, grant listings, tender listings, funding body pages, and other third-party resources. These links are provided for your convenience and do not constitute an endorsement, referral, or recommendation by ECHO Projects.
This Privacy Policy applies only to our Services. External websites and services have their own privacy policies and data practices, which we do not control and are not responsible for. We encourage you to read the privacy policies of any external services you access through links from our platform.
In particular, AusTender (austender.gov.au), GrantConnect (grants.gov.au), The Grants Hub, and individual funding body websites are operated by government agencies and third parties under their own terms and privacy frameworks.
17. Children and young people
The Services are intended for use by individuals aged 16 years and over, and are directed at organisational users, nonprofit representatives, grant applicants, and business operators. The Services are not directed at or designed for children under 16.
We do not knowingly collect personal information from children under 16 years of age. If you are under 16, you should not use the Services or provide personal information to us.
If a parent, guardian, or authorised representative believes that a child under 16 has provided personal information to us, they should contact us promptly at Admin@ECHOProjects.org so we can assess and, where appropriate, delete that information.
If a user is aged 16 or 17, we recommend that they use the Services with the knowledge and supervision of a parent, guardian, or responsible adult. Where an individual under 18 provides sensitive information or uploads documents, we will handle that information with particular care consistent with applicable Australian law.
18. Your rights — access, correction and deletion
Under the Privacy Act and the APPs, you have rights in relation to your personal information. These include:
Right to access (APP 12)
You may request access to personal information we hold about you. We will respond within a reasonable period and, where the Privacy Act applies, generally within 30 days. We may need to verify your identity before actioning a request. We may charge a reasonable fee for access if the request is complex or resource-intensive, but we will notify you before incurring any charge.
We may lawfully refuse access in certain circumstances, including where providing access would unreasonably impact another person's privacy, prejudice an enforcement activity, reveal commercially sensitive information, be frivolous, vexatious, or otherwise be contrary to law. If we refuse access, we will provide reasons where lawful and practicable, and explain how you can make a complaint.
Right to correction (APP 13)
You may ask us to correct personal information you believe is inaccurate, out of date, incomplete, irrelevant, or misleading. We will take reasonable steps to correct it, or to add a notation to the record if we decline to correct it. If we decline, we will explain why and how you can make a complaint.
Right to request deletion
You may request deletion of your account and personal data. We will process deletion requests within a reasonable time. Some information may be retained after deletion where required by law — particularly billing and transaction records for 7 years under Australian tax law, and complaint or dispute records where a matter is unresolved.
Other rights and requests
- Withdrawal of optional consents (e.g. opting out of marketing communications).
- Deletion of specific uploaded documents or project records within the Services (many of which can be done directly in the platform).
- Export of reasonably available data relating to your account, subject to feasibility and any applicable limitations.
- Questions about how your information is being used or disclosed.
To exercise any of the above rights, contact us at Admin@ECHOProjects.org or by phone on 0493 051 823. We aim to acknowledge all privacy requests within 5 business days. You can also update certain account, project, and profile information directly within the Services at any time.
19. Privacy complaints and regulators
If you have a privacy concern, complaint, or question about how we have handled your personal information, please contact us first so we can investigate and seek to resolve it directly.
Privacy Officer — ECHO Projects
Email: Admin@ECHOProjects.org
Phone: 0493 051 823
Please mark your subject line: Privacy Complaint
We aim to acknowledge privacy complaints within 5 business days and to provide a substantive response within 30 days where practicable. Complex or novel complaints may require more time, in which case we will provide progress updates at reasonable intervals and an indicative resolution timeline.
Our complaint handling process includes: (1) acknowledgment; (2) investigation of the facts; (3) assessment against applicable privacy law; (4) a written response setting out our findings, any proposed remedial action, and (if applicable) any corrective steps we will take; and (5) notification of your right to escalate if you remain unsatisfied.
External regulators
If you are not satisfied with our response, or if we fail to respond within 30 days, you may escalate your complaint to:
- Office of the Australian Information Commissioner (OAIC) — oaic.gov.au | 1300 363 992. The OAIC handles complaints about Australian Privacy Principle entities under the Privacy Act 1988 (Cth).
- Information and Privacy Commission NSW (IPC NSW) — ipc.nsw.gov.au | 1800 472 679. The IPC handles complaints about NSW public sector privacy and health privacy in NSW. Whether IPC has jurisdiction over Grant Scan depends on the specific circumstances.
- Australian Competition and Consumer Commission (ACCC) — accc.gov.au — for concerns about misleading conduct relating to privacy representations.
20. Limitation of liability and no warranty
To the maximum extent permitted by Australian Consumer Law and other applicable law, ECHO Projects makes no warranty, representation, or guarantee (express or implied) that:
- Any grant or tender recommendation is accurate, current, complete, or appropriate for your circumstances.
- Your project or organisation is eligible for any grant or tender identified by the Services.
- The Services will be available without interruption, error, or loss of data.
- Any AI-generated output is free from error, bias, or hallucination.
- The platform's grant or tender database is comprehensive or up to date.
Nothing in this Policy or our Terms of Service excludes, restricts, or modifies rights under the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)) or other rights that cannot lawfully be excluded. Where liability cannot be excluded, it is limited to the maximum extent permitted by law.
21. Changes to this Policy
We may update this Policy from time to time to reflect changes in applicable law or regulatory guidance, changes to our technology, infrastructure, or service providers, changes in our products or business practices, or for any other lawful reason.
The current version of this Policy will always be available at grantscan.echoprojects.org/PrivacyPolicy, free of charge. Each version is identified by an effective date and a last-updated date shown at the top of this page.
If we make material changes to this Policy — for example, changes to how we use personal information, a new category of disclosure to third parties, or significant changes to data retention practices — we will take reasonable steps to notify users, which may include:
- Updating the "Last updated" date prominently at the top of this page.
- Posting a notice in the application or on our website.
- Sending an email notification to registered users.
Your continued use of the Services after a material change takes effect constitutes acceptance of the updated Policy. If you do not accept any change, you must stop using the Services and may request deletion of your account subject to lawful retention obligations. We recommend you review this Policy periodically.
22. Compliance sources considered
This Policy was drafted and reviewed with reference to the following official Australian and NSW privacy materials current at the time of update:
- Privacy Act 1988 (Cth) — the 13 Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme (Part IIIC), and all associated OAIC guidelines.
- Privacy and Other Legislation Amendment Act 2024 (Cth) — including privacy tort provisions, automated decision-making transparency requirements (APP 1 changes commencing December 2026), and children's privacy register provisions.
- OAIC APP Guidelines — including APP 1 (open and transparent management), APP 3 (collection of solicited information), APP 4 (unsolicited information), APP 5 (notification), APP 6 (use and disclosure), APP 7 (direct marketing), APP 8 (cross-border disclosure), APP 10 (data quality), APP 11 (security), APP 12 (access), APP 13 (correction).
- OAIC Notifiable Data Breaches scheme guidance and assessment methodology.
- OAIC guidance on data minimisation, privacy by design, and privacy management frameworks.
- Privacy and Personal Information Protection Act 1998 (NSW) — the 12 Information Protection Principles, considered as a good-practice benchmark.
- Health Records and Information Privacy Act 2002 (NSW) — the 15 Health Privacy Principles, considered in relation to any incidental health information.
- Spam Act 2003 (Cth) — requirements for consent, sender identification, and unsubscribe mechanisms for commercial electronic messages.
- Competition and Consumer Act 2010 (Cth) — Schedule 2 (Australian Consumer Law) — in relation to representations made about the Services.
- Income Tax Assessment Act 1997 (Cth) and related ATO guidance on record-keeping obligations (general 5–7 year retention for business records).
- OpenAI API data usage policy and data processing addendum.
- Stripe Privacy Policy (stripe.com/au/privacy) and Stripe Services Agreement.